Secrets Rotation Audit
Phase 1: Secrets Inventory
Catalog all secrets and credentials in scope.
| Secret ID |
Type |
Service/Owner |
Created |
Last Rotated |
Age (days) |
Rotation Policy |
Compliant |
|
|
|
|
|
|
|
|
Secret Types: API Key, Database Credential, TLS Certificate, SSH Key, OAuth Token, Service Account Key, Encryption Key, Webhook Secret
Phase 2: Compliance Assessment
Evaluate each secret against the rotation policy.
Compliance by Type:
| Secret Type |
Total |
Compliant |
Non-Compliant |
Compliance Rate |
| API Keys |
|
|
|
|
| DB Credentials |
|
|
|
|
| TLS Certificates |
|
|
|
|
| SSH Keys |
|
|
|
|
| Service Account Keys |
|
|
|
|
| Other |
|
|
|
|
Phase 3: Risk Assessment
For each non-compliant secret, assess risk.
Decision Matrix:
| Risk |
Criteria |
Action |
| Critical |
Secret >2x policy age, has broad permissions, no MFA protection |
Rotate immediately, investigate for compromise |
| High |
Secret >policy age, used in production, shared across services |
Rotate within 48 hours |
| Medium |
Secret >policy age, limited scope, single-service use |
Rotate within 7 days |
| Low |
Secret approaching policy age, rotation scheduled |
Ensure scheduled rotation proceeds |
Phase 4: Automation Assessment
Phase 5: Remediation Plan
For each non-compliant secret:
-
-
-
-
-
Counter-Rationalizations
| Shortcut |
Counter |
Why |
| "We can skip some steps for this case" |
Adapt the workflow steps, don't skip them |
Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" |
Complete all workflow phases with the user |
The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" |
Scale the process down, don't turn it off |
Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" |
Complete each section before moving on |
Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" |
Always produce the structured output format |
Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
Summary
- Total secrets audited: ___
- Overall compliance rate: ___%
- Critical/High risk secrets requiring immediate rotation: ___
- Automated rotation coverage: ___%
Action Items
1---2name: secrets-rotation-audit3description: Use when performing secrets rotation audit — audits the rotation status of all secrets, credentials, API keys, and certificates across services and environments. This template identifies stale secrets, missing rotation policies, and non-compliant credential management practices, producing a remediation plan to strengthen secrets hygiene.4---56# Secrets Rotation Audit78## Phase 1: Secrets Inventory910Catalog all secrets and credentials in scope.1112| Secret ID | Type | Service/Owner | Created | Last Rotated | Age (days) | Rotation Policy | Compliant |13|-----------|------|---------------|---------|-------------|------------|-----------------|-----------|14| | | | | | | | |1516**Secret Types:** API Key, Database Credential, TLS Certificate, SSH Key, OAuth Token, Service Account Key, Encryption Key, Webhook Secret1718## Phase 2: Compliance Assessment1920Evaluate each secret against the rotation policy.2122- [ ] Total secrets inventoried: ___23- [ ] Secrets within rotation policy: ___24- [ ] Secrets overdue for rotation: ___25- [ ] Secrets with no rotation policy: ___26- [ ] Secrets with unknown last rotation date: ___2728**Compliance by Type:**2930| Secret Type | Total | Compliant | Non-Compliant | Compliance Rate |31|-------------|-------|-----------|---------------|-----------------|32| API Keys | | | | |33| DB Credentials | | | | |34| TLS Certificates | | | | |35| SSH Keys | | | | |36| Service Account Keys | | | | |37| Other | | | | |3839## Phase 3: Risk Assessment4041For each non-compliant secret, assess risk.4243**Decision Matrix:**4445| Risk | Criteria | Action |46|------|----------|--------|47| Critical | Secret >2x policy age, has broad permissions, no MFA protection | Rotate immediately, investigate for compromise |48| High | Secret >policy age, used in production, shared across services | Rotate within 48 hours |49| Medium | Secret >policy age, limited scope, single-service use | Rotate within 7 days |50| Low | Secret approaching policy age, rotation scheduled | Ensure scheduled rotation proceeds |5152- [ ] Check for secrets stored in plaintext (code repos, config files, wikis)53- [ ] Identify secrets shared across multiple services or teams54- [ ] Verify secrets are accessed only by authorized principals55- [ ] Check for leaked secrets in public repositories or logs5657## Phase 4: Automation Assessment5859- [ ] Percentage of secrets with automated rotation: ___%60- [ ] Secrets manager integration coverage: ___%61- [ ] Rotation automation tool: ___62- [ ] Gaps in automation (manual rotation still required): list6364## Phase 5: Remediation Plan6566For each non-compliant secret:67681. - [ ] Rotate the secret692. - [ ] Update all consumers of the secret703. - [ ] Verify service continuity after rotation714. - [ ] Enable automated rotation if not already configured725. - [ ] Document rotation procedure7374## Counter-Rationalizations7576| Shortcut | Counter | Why |77|----------|---------|-----|78| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |79| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |80| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |81| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |82| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |8384## Output Format8586### Summary8788- **Total secrets audited:** ___89- **Overall compliance rate:** ___%90- **Critical/High risk secrets requiring immediate rotation:** ___91- **Automated rotation coverage:** ___%9293### Action Items9495- [ ] Rotate all Critical risk secrets immediately96- [ ] Rotate all High risk secrets within 48 hours97- [ ] Enable automated rotation for all eligible secrets98- [ ] Remove any plaintext secrets from code or config99- [ ] Establish quarterly secrets rotation audit cadence100- [ ] Report compliance status to security team